Impact
The vulnerability is a NULL dereference in the Linux kernel’s NFSv4 implementation, specifically in flexfiles handling of NFSv4.0 data servers. When a client without a session pointer communicates with the server, the kernel dereferences a null session pointer during lease seeding and error handling, causing a crash. This permits an attacker to force a kernel panic, disrupting system availability and providing a denial‑of‑service vector.
Affected Systems
All Linux distributions that ship the Linux kernel without the applied kernel patch are potentially impacted. The issue existed in older kernel releases before the commit referenced in the advisory. Users running those kernels on any vendor’s Linux system—whether servers, desktops, or embedded devices—are at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% implies a low but present likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, and no public exploits have been reported. The likely attack vector is through network NFS traffic from a client using NFSv4.0, which may be exploitable remotely if the server’s NFS daemon is reachable. Given the lack of known exploits, the current risk to production systems is moderate, but the impact of a kernel crash is severe.
OpenCVE Enrichment